<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Ceph - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/ceph/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 09 Aug 2026 09:36:24 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/ceph/feed.xml" rel="self" type="application/rss+xml"/><item><title>Memory Safety Vulnerability in libceph decode_lockers()</title><link>https://feed.craftedsignal.io/briefs/2026-08-libceph-unsafe-decodes/</link><pubDate>Sun, 09 Aug 2026 09:36:24 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-libceph-unsafe-decodes/</guid><description>CVE-2026-68082 describes two unsafe bare decode operations within the libceph decode_lockers() function that could lead to memory corruption during network data deserialization.</description><content:encoded><![CDATA[<p>Microsoft has disclosed CVE-2026-68082, involving two instances of unsafe bare decodes within the decode_lockers() function of the libceph library. These vulnerabilities stem from improper handling of data during the deserialization process of incoming network traffic. When a Ceph component processes specially crafted network input, these unsafe decoding operations can lead to memory safety violations, potentially resulting in memory corruption, process crashes, or other undefined behavior within the Ceph infrastructure. Organizations utilizing Ceph storage clusters should review their dependency versions and apply security updates provided by the Ceph project to remediate these deserialization flaws.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of these vulnerabilities could result in memory corruption within the libceph library, potentially leading to denial of service through process termination or the corruption of internal memory structures. The impact is primarily focused on storage environments relying on libceph for data handling and management.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the identification and patching of the libceph library across all storage infrastructure components to the version containing the fix for CVE-2026-68082. Use software composition analysis (SCA) tools to inventory the use of libceph within existing applications and container images.</p>
]]></content:encoded><category domain="severity">medium</category><category domain="type">threat</category></item></channel></rss>